PatchSiren

deskflow CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM deskflow CVE published 2026-08-17

CVE-2026-65976

A vulnerability in Deskflow, a keyboard and mouse sharing app, allows a connected peer to send repeated DCLP DataChunk messages to ClipboardChunk::assemble() in src/lib/deskflow/ClipboardChunk.cpp. This causes the server path in src/lib/server/ClientProxy1_6.cpp or client path in src/lib/client/ServerProxy.cpp to append data beyond the DataStart declared size and configured clipboard limit before DataEnd [truncated]

HIGH deskflow CVE published 2026-08-17

CVE-2026-65832

CVE-2026-65832 is a high-severity vulnerability in the Deskflow keyboard and mouse sharing app. A remote, unauthenticated Deskflow server can send specially crafted messages to connected clients, potentially disclosing sensitive information or crashing the client. The issue is fixed in continuous build 1.26.0.299. This vulnerability allows for potential information disclosure or client crashes due to out- [truncated]

HIGH deskflow CVE published 2026-08-17

CVE-2026-63409

CVE-2026-63409 is a high-severity vulnerability in the Deskflow keyboard and mouse sharing app. A malicious Deskflow server can send a specially crafted DSOP vector to crash connected clients. The issue was fixed in continuous build 1.26.0.296. This vulnerability affects Deskflow users who have not updated to the fixed version, potentially leading to client crashes. Defenders should verify exposure and ap [truncated]